Trust & Security Centre

Security controls you can verify.

Brolly holds the records your organisation may one day need to produce for an FOI request, an audit or a court. That responsibility shapes how the platform is built, audited and operated — and everything on this page is verifiable. Questions go to security@brolly.com.au.

Certifications

Independently certified, not self-declared.

ISO/IEC 27001:2022 certification badge — SouthPac Certifications Certified

ISO/IEC 27001:2022

Brolly Australasia Pty Ltd holds a certified information security management system — the international benchmark, audited independently.

Download the certificate (PDF)
CSA STAR Level One Self-Assessment badge Registered

CSA STAR

Registered with the Cloud Security Alliance's Security, Trust & Assurance Registry.

View the public registry listing
Aligned

Australian ISM & Essential Eight

Practices aligned to the Australian Government Information Security Manual and the ASD Essential Eight mitigation strategies.

Control mapping on request
Compliance alignment

Built for the rules your records live under.

Brolly's security practices are aligned to the Australian Government Information Security Manual (ISM) and the ASD Essential Eight. These frameworks guide how we approach security, risk management and operational resilience for councils, agencies and regulated organisations. For multinational or US reviews, our controls are also mapped to NIST SP 800-53.

Your obligationWhat it demandsHow Brolly answers
State records legislation & FOI / GIPA / RTIProduce responsive, unaltered records on request — including edited and deleted contentNear-real-time capture, revision history, response-ready exports with digital checksums
ASIC RG 271 (financial services)Handle complaints made through social media like any other complaint, with a recordRecords retained until you authorise disposal, with audit trails
Health & education communitiesHandle sensitive communities' communications with care and accountabilityRole-based access, moderation with preserved records, audit logs
Retention and disposal authoritiesKeep records for the required periods, then dispose of them defensiblyConfigurable retention aligned to your retention and disposal authority
Platform security

The controls, in plain English.

Where your data lives: Your data is stored on AWS cloud servers located in Australia. Brolly is 100% Australian owned and operated, and Brolly Australasia Pty Ltd is the certified entity.

Encryption everywhere

AES-256 at rest, TLS 1.3+ in transit. Records carry audit logs; exports carry digital checksums.

Access control

Multi-factor authentication and role-based access — records team, comms team and legal each see what their role requires.

Tested by attackers

Independent penetration testing and a secure development lifecycle guided by OWASP practices.

Reliable by design

Redundant AWS architecture in Australia across multiple availability zones, encrypted backups, and an availability commitment set out in our service level agreement.

Privacy

Your records are yours.

Brolly never sells customer data and never shares it for third-party advertising. Approved subprocessors, such as our hosting providers, process it only to provide and secure the service under contractual safeguards. Our privacy practices are built around the Australian Privacy Act and the Australian Privacy Principles, with GDPR-ready handling where you need it and data deletion honoured per our published process.

Australian Privacy ActGDPR-ready practicesNo data selling — everDocumented deletion processAudit trails on every action
Security review

What your security team will ask.

Is Brolly ISO 27001 certified?
Yes — Brolly Australasia Pty Ltd is certified against ISO/IEC 27001:2022, the international standard for information security management, and is registered with the Cloud Security Alliance STAR program. The certificate and the registry listing are both public.
Which frameworks do Brolly’s controls align to?
Brolly’s security practices are aligned to the Australian Government Information Security Manual (ISM) and the ASD Essential Eight, Completed security questionnaires and control mappings are available under NDA for your assessment.
Is our data stored in Australia?
Your data is stored on AWS cloud servers located in Australia. Records are encrypted with AES-256 at rest and TLS 1.3+ in transit, with digital checksums on every export, and protected by multi-factor authentication, role-based access controls and audit trails covering sign-ins, exports, moderation actions and role changes. Records are retained until your organisation authorises disposal.
Do you sell or share our data?
No. Brolly never sells customer data and never shares it for third-party advertising. Approved subprocessors, such as our hosting providers, process it only to provide and secure the service under contractual safeguards. Our privacy practices are built around the Australian Privacy Act and the Australian Privacy Principles, with GDPR-ready handling for organisations that need it.
What uptime do you commit to?
A service availability commitment backed by service credits, set out in our service level agreement, on redundant AWS infrastructure with encrypted backups across multiple availability zones.
Can our security team review your controls?
Yes — certification documents, penetration-test summaries and completed security questionnaires are available under NDA. Email security@brolly.com.au and we’ll route you to the right people.

Send us the questionnaire. We like them.

Certification documents, pen-test summaries and completed security reviews are available under NDA.